Comments (13)
Do you mean these Apache mod_ssl parameters? We do expose them as server_ssl_{ca,cert,key,chain,crl}. You should also override websockets_ssl_{key,cert} if you use websockets.
Katello also uses these because they don't use puppet for certificate management. It appears they use foreman-rake config
to set these config values. They should use foreman_config_entry
and maybe you're right that puppet-foreman should expose this. See https://github.com/Katello/puppet-certs/blob/8ed3854fffc2a4824d726352ff1bf2397c569c5c/manifests/foreman.pp#L51-L63
from puppet-foreman.
Do you mean these Apache mod_ssl parameters?
No. I don't care for them.
You should also override websockets_ssl_{key,cert} if you use websockets.
I do that.
For you do expose them in settings.yaml.erb
It appears they use foreman-rake config to set these config values. They should use foreman_config_entry
Yeah, but I don't use puppet either.
I've written simple Ansible role where I render foreman-answers.yaml file and let foreman-installer take care of things
but he knows nothing about ssl_ca_file, ssl_certificate and ssl_priv_key
Currently foreman-installer does not let me configure custom_config_entries either
so
for now I use ugly ansible hack for configuring the stuff I want.
And it makes me sad.
from puppet-foreman.
Thanks for the additional description of your use case.
I wonder what @mmoll, @domcleal and @brandonweeks think about this. Should we include these values in settings.yaml or use foreman_config_entry? And should we always manage those values or expose the as separate variables?
from puppet-foreman.
I don't think I'd mind them being always managed in settings.yaml, as it's quite common to want to override them. It may come as a surprise to anybody who's changed them already though on upgrade.
from puppet-foreman.
If you set them in settings.yaml I don't think you can override them in the UI, though that may also surprise some users.
from puppet-foreman.
Indeed, though I think it does show a tooltip explaining where it's set. The only problem with relying a lot on foreman_config_entry is the speed, it's relatively slow to run a rake task (though we can also improve this with Puppet provider prefetch/flush features).
from puppet-foreman.
If the UI is clear about it, I'd prefer settings.yaml.
from puppet-foreman.
from puppet-foreman.
I think we should introduce separate variables which have the same defaults, agreed?
from puppet-foreman.
I'm OK with that.
from puppet-foreman.
Thanks!
When will new foreman-installer be available with those params?
from puppet-foreman.
They would be in the next major version, 1.12 (http://projects.theforeman.org/projects/foreman/wiki/Foreman_112_Schedule).
from puppet-foreman.
Great!
Thanks guys.
You rock!
from puppet-foreman.
Related Issues (20)
- provide a new release that's compatible with puppetlabs/postgresql 8 HOT 3
- foreman_config_entry type does not deal well with array data
- Support apt module v9.x HOT 1
- Puppet Environments/Modules are not updated HOT 4
- puppetlabs/apache: Allow 9.x HOT 1
- Consider using stdlib::ensure_packages HOT 1
- Clicking host hyperlink for puppetclass (under Puppet ENC -> Classes) returns "Field 'class' not recognized for searching!"
- Permissions for foreman::app_root not set correctly HOT 3
- foreman-report_v2 disappeared from master branch ? HOT 2
- Allow customising request header filtering in vhost internal options
- Customisable Yum repository base URL HOT 1
- Allow configuring the priority of the Yum repositories
- Allow customising ProxyAddHeaders
- Feature request: type & provider for "Global Parameters" HOT 2
- Any plans to migrate from camptocamp-systemd to puppet-systemd ? HOT 2
- foreman_config_entry consuming polluted value HOT 4
- Ensuring the ruby module stream on rhel 8 HOT 9
- stale references to some 'globals' variables HOT 2
- Service 'foreman' is started unconditionally HOT 1
- Explicit empty foreman::user_groups parameter does not prevent 'puppet' group addition HOT 3
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from puppet-foreman.